# Scripted Field EsError in Kibana

**URL:** <https://discuss.elastic.co/t/scripted-field-eserror-in-kibana/274542>\
**Category:** Kibana\
**Created:** [May 31, 2021, 6:00pm UTC](https://discuss.elastic.co/t/scripted-field-eserror-in-kibana/274542 "2021-05-31T18:00:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![opdelta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opdelta/32/89547_2.png) [@opdelta](https://discuss.elastic.co/u/opdelta)\
**Post date:** [May 31, 2021, 6:00pm UTC](https://discuss.elastic.co/t/scripted-field-eserror-in-kibana/274542/1 "2021-05-31T18:00:06Z")

</div>

Hey there,  
I have Apache logs imported in ES where the "request.keyword" field contains the path of the accessed document of a server. For example: "/category/path/to/requested/data/xml/file.xml"  
I want to sort in a dashboard the category of the requested file instead of the full path to have like a pie chart for example of all the "Category 1" together instead of each individual category1/etc/file.xml.

I created the following scripted field:

```auto
def path = doc['request.keyword'].value;
if (path != null) {
    int secondIndex = path.indexOf('/', path.indexOf('/') + 1);
    if (secondIndex > 1) {
        return path.substring(1, secondIndex);
    }
}
return "";

```

When I go over to the discover tab, the new scripted field seems to work perfectly. (See image)

 ![script](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f5c9af2e9d3cb95fa8ed88c8e0ec2938e26fe18.png)  
When I go over to Lens in Kibana to create a visualization of all the "categories", I get the following error:  
 ![error](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29034b0d9939e777aad8eaf0c4fbeb64da127bc1.png)  
(Alternative picture location: [Imgur: The magic of the Internet](https://imgur.com/a/IBQdFvv))  
`An error occurred when loading data. [lens_merge_tables] > [esaggs] > EsError"`  
I don't understand why the scripted field works, but doesn't let me visualize the data extracted by it.

Any help would be appreciated, I will be glad to provide extra information!  
Thanks

---

<div class="post-metadata">

**Author:** ![opdelta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opdelta/32/89547_2.png) [@opdelta](https://discuss.elastic.co/u/opdelta)\
**Post date:** [June 1, 2021, 3:38pm UTC](https://discuss.elastic.co/t/scripted-field-eserror-in-kibana/274542/2 "2021-06-01T15:38:18Z")

</div>

An amazing soul helped me out with this problem and it is now fixed.

For anyone else having this problem, here's what I ended up doing.

```auto
if (!doc.containsKey('request.keyword') || 
    doc['request.keyword'].empty) {
    return "Not present in doc";
} else {
    def path = doc['request.keyword'].value;
    if (path != null) {
        int secondIndex = path.indexOf('/',path.indexOf('/') + 1);
        if (secondIndex > 1) {
            return path.substring(1, secondIndex);
        }
    }
return "";
}

```

I added a more thorough check at the beginning that checks if the doc contains the key and if it is empty.  
It fixed it for me and I hope it fixes it for you as well.

Credits to u/ratonbox. Original answer: [https://www.reddit.com/r/kibana/comments/npblcy/scripted\_field\_eserror\_in\_kibana/](https://www.reddit.com/r/kibana/comments/npblcy/scripted_field_eserror_in_kibana/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2021, 3:38pm UTC](https://discuss.elastic.co/t/scripted-field-eserror-in-kibana/274542/3 "2021-06-29T15:38:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
